
The GC+CISO Connection · 2026-04-28 · 35 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
Jenny Gray brings a retail executive perspective to crisis management that mirrors cyber incident response challenges. As a lawyer who managed Tuesday Morning's rapid descent from bankruptcy filing to liquidation between February and August 2023, she emphasizes the criticality of transparent communication, cross-functional team relationships, and maintaining fiduciary duties to employees, customers, and shareholders during chaos. Gray highlights how cyber crises share unique characteristics with business crises: victims are often blamed as wrongdoers, the impact touches every department requiring unprecedented coordination, and decisions must be made at speed with incomplete information. She stresses the importance of building relationships and understanding team dynamics before crisis hits, teaching the "why" behind policies to drive ownership, and communicating hard truths to employees rather than speculation. The conversation also touches governance as a framework for navigating gray areas, privacy and cybersecurity as board-level concerns, and emerging challenges like AI governance where companies must accept agency and responsibility for tools they deploy. For GCs and CISOs, Gray's experience demonstrates how legal, operational, and security teams must partner effectively when everything moves at crisis velocity.
Tuesday Morning, a Dallas-based off-price retailer operating in 47 states, filed for bankruptcy in February 2023 and liquidated by August 2023. Gray served as one of the final two employees managing the closure, dealing with decisions at crisis velocity while balancing duties to shareholders, employees, and customers.
Gray feared employees would leave immediately if told the full truth, but discovered that transparent communication about the company's closure actually increased employee retention. Staff wanted to finish the business well and responded to honest, timely information even when it was difficult.
Both involve victim organizations being blamed as wrongdoers, require unprecedented cross-functional coordination across all departments, demand decisions at high speed with incomplete information, and benefit enormously from pre-crisis relationship-building and clear communication of rationale.
Retailers handle customer information, employee data, applicant records, and vendor information across multiple state and international jurisdictions (including GDPR), creating legal complexity that boards now scrutinize heavily and that fundamentally affects customer trust.
Companies must accept responsibility and agency for AI tools they deploy, similar to how they're held accountable during crises. Transparency about AI use and governance frameworks are essential because courts hold organizations responsible for tool outputs, as demonstrated by the Air Canada chatbot case.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid practical principles about crisis management (transparency, team collaboration, moving slow during fast crises) and some useful observations about GC/CISO partnerships, but relies heavily on anecdotes and general wisdom rather than novel, data-backed insights. Most takeaways are established best practices (building relationships before crisis, avoiding ego, being transparent) that experienced operators would already know.
in crisis is everything moves fast, so you move slow
you have to always be the calmest on the outside person in the room
The episode recycles familiar frameworks - transparency in crisis, importance of preparation and relationships, ego as a barrier to collaboration - without introducing fresh or contrarian thinking. The parallel drawn between bankruptcy crisis management and cyber crisis is useful but not deeply original. No first-principles reasoning or genuinely counterintuitive arguments emerge.
there was a fear of when you start talking about it in reality
governance tells me where we can go and where we should go
Jenny Gray is a legitimate operator - VP/AGC at a public company, hands-on experience managing corporate bankruptcy and liquidation at scale, direct involvement in privacy/security/risk. She has actually done the work at material scale (Torrid, Tuesday Morning), making her more credible than pure thought leaders. However, she's speaking from a legal/GC perspective rather than as a CISO or IT security leader, limiting depth on technical cyber crisis response.
I am the vice president of legal assistant general counsel at Torrid
Tuesday Morning, which was an off price retailer...filed for bankruptcy in 2020 and...filed for bankruptcy again and ultimately...was liquidated
The episode lacks concrete metrics, timelines, and dollar figures. Tuesday Morning crisis is described narratively but without specifics (e.g., how many employees, liquidation timeline details, financial impact). Discussion of privacy/compliance references named regulations (GDPR, SoC2) but with minimal concrete examples. Most claims are illustrative rather than evidenced with data.
it was in like 47 states at one point
from in February of filing bankruptcy to ultimately we handed the keys over to a trustee about August 1st
The host asks solid foundational questions and creates space for thoughtful responses, particularly around governance definitions and crisis lessons. However, follow-ups are often gentle and confirmatory rather than probing or challenging. The host doesn't press on contradictions (e.g., transparency vs. operational security, or specific metrics for success). The conversation feels collaborative but lacks the edge of genuine intellectual push-back.
And what does it mean to you? What is government?
I remember you talking about the team you relied on and starting with your outside counsel
Computed from the transcript - who did the talking, and the words that came up most.
Episode Overview In this episode, host Shawn Tuma welcomes Jenny Gray, VP of Legal and Assistant General Counsel at Torrid, to discuss her firsthand experience guiding her previous employer, Tuesday Morning, through bankruptcy and liquidation - and what those hard-won lessons mean for GCs and CISOs facing cyber crises today. The conversation covers crisis team-building, transparent communication under pressure, the dangers of ego, and the growing connection between cyber attacks and financial collapse. About the Guest Jenny Gray is Vice President of Legal and Assistant General Counsel at Torrid, a national publicly traded women's retailer. A Dallas native and SMU Law graduate, Jenny's career has spanned retail, governance, privacy, sustainability, and risk management. Key Topics Covered The Tuesday Morning Bankruptcy - Jenny recounts leading legal through Tuesday Morning's 2023 bankruptcy filing and liquidation, from the quiet crisis before filing to handing the keys to a trustee by August 1 - all in roughly six months at lightning speed.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Since the late 90s, Sean Tooma has been working with legal departments and security teams at the intersection of law and technology. This has given him a unique perspective for how these important defenders work well together and do not work well together. And what a difference that can make with how their organizations manage cyber risk. This led him to write a book called the GC CISO Connection to help start a dialogue and strengthen the partnership between the critically important roles. The next step is to bring together people who understand these roles to share their experiences and continue the dialogue. Because none of us have all the answers. It is through conversations like these that we can all improve how we work together to improve cyber resilience. This is the GCCISO Connection Show.
Speaker B: Hello and welcome to the GC CISO Connection Show. I'm your host, Shawn Tuma, and joining me today is my friend Jenny Gray. Jenny, welcome to the show.
Speaker C: Hi. It's so great to be here today. Thank you.
Speaker B: It's a pleasure to have you and thank you for joining me.
Speaker C: Anytime.
Speaker B: Yep. So, Jenny, if you will, uh, tell us what your title is. Sure.
Speaker C: I am the vice president of legal assistant general counsel at Torrid. It is a national women's retailer. Uh, okay, great.
Speaker B: And what do you. What does that mean for your day to day job of what you do as assistant vice president and. Or was it vice president, assistant assistant general counsel?
Speaker C: It's a whole bunch of letters. I lawyer. Right.
Speaker B: Good with all the formalities.
Speaker C: Bunch of lawyering. Uh, so my day to day in retail is always kind of interesting because I don't necessarily get to pick it. It's a little of, uh, what comes down the conveyor belt. Um, we are a publicly traded company, so I do a lot of governance work. But um, my lot in life seems to be that in the past several jobs I support it frequently and do a lot of work. And I would say privacy and sustainability and risk. So, um, I am a sky is falling girl. Right. So lots of problems and issues that come up in those areas.
Speaker B: Yeah. Now I want to ask you something because you mentioned governance and there's a lot of confusion sometimes in the security community over what governance means. Um, I was fearful of that word for about 20 years of my career because had these like overwhelming connotations about it.
Speaker C: Sure.
Speaker B: And it wasn't until later I realized it really wasn't as complicated as it sounded like by definition, not now to do, it's very different. But what does it mean to you? What is government?
Speaker C: So I think that's a great question. I will tell you that I love governance. I think of it as a ruby. And governance tells me where we can go and where we should go. And I think the other thing governance says is it tells other people how you're going to play the game. And I find governance to be very comforting in that and that so many things legally are super gray. And that's where we work. Right. Is in dealing with that. And governance helps me a little bit dilute that gray and figure out what's happening and where it's going. So. So what we need to be doing.
Speaker B: I like that. Uh, now I'm also wondering, do we have a new nickname for you? Super Gray. Um, are we gonna make this stick?
Speaker C: That would be a hot mess. I'll stick with just Jenny.
Speaker B: No, I like that. I appreciate that. Because there is a lot of confusion out there about what that means.
Speaker C: Yeah, well, and I think people in it especially are always very concerned, uh, when a lawyer comes in the room. Cause they think you're going to try and step in and, and tell them what they can or can't do in their job or how to do their job. And that's always a slippery slope because they are, without a question, they're the experts, um, in systems and securities and other parts. And it's always my job to support and kind of guide, um, a little bit, but not to overtake or overstep because then my computer is not going to work, I'm sure. Yeah, they can be good and spiteful.
Speaker B: Yours will be the one that's that
Speaker C: meeting that's always right. Have you hit control, alt, delete? Like I'll have all those problems.
Speaker B: Yep. I was actually at an event yesterday where someone got ready to do their presentation with their laptop and it started updating. I've had it happen.
Speaker C: Yeah, absolutely. Haven't we all? I think it's just the nature of the game. Right.
Speaker B: Yeah, it really is. So, Jenny, how did you get to where you are today? Give us a little bit of your background.
Speaker C: Sure. Um, I will tell you. I am a Dallas girl. These are my people. This is my town. Um, I grew up in Duncanville. I went to SMU undergrad, SMU law school. And no one is more shocked that than me that I am in house. This was never the path that I thought I would take. Um, and I love it and can't imagine. And then second to that, working, uh, in retail really surprises me because it's a little secret. I'll tell. I am not a shopper and so. But I like the pace of Retail. And I like the problems and crisis that you get in retail. So I stay and IT think, um, I've been involved in the IT type world for years now and I think it's because I'm bad at it. And it has stretched and pulled me in ways I would have never thought. Um, and taught me something, um, more than anything else because I was always the person who was surprised my computer turned on when I hit it on. I absolutely had no idea how all of these things worked. I certainly didn't understand the Internet. And now I see spend a large chunk of my days talking about IT type issues. And I find that fascinating. Right. To, to go from one end of a pendulum to another to learn something.
Speaker A: Yeah.
Speaker B: And you know, I really love that. Um, because that's what, you know, we were talking about the partnership, the relationship between IT and legal. I mean that's the whole message of this show and the book and all that other stuff was that partnership and how we have to work together. But I'm really thinking about something else as we talk about this. Um, sometimes the best way to teach is when you learn something.
Speaker C: Absolutely.
Speaker B: Starting from zero. Because you're not making assumptions, you're not taking things for granted. And you know, Jenny, one of the, one of the points I make when I do like client trainings and stuff, um, and I did one this week in Utah, is I talk about the need to teach our policies and procedures, not just push them out and say, go follow this right 100%, but to teach. And for me that comes from having six children.
Speaker C: Yeah.
Speaker B: Because they may be the most wonderful, brilliant, beautiful children in the world, but if we don't teach them, they're not going to follow that. And you have six children also.
Speaker C: I do, I do. So we have that in common. I, I think an interesting component of teaching is understanding and taking ownership. And I think once you have buy in of why things are necessary or required, if you can get that buy in with it, you have effectuated a change that will be long lasting. If I put together some SOP and I roll it out and I don't give the why, there's no ownership, um, you've got to tell people, this impacts your job this way, this impacts our company this way. And if you're not willing to invest on that, you're not going to have the outpouring of success that you want for your company.
Speaker B: Uh, I agree 100% and I actually use that example of the why, because that's something I learned first at home. You know, I can tell my kids all day long not to do something, but if I don't explain the why, they are absolutely, absolutely not gonna, you know, because it doesn't mean anything. It's the why that matters.
Speaker C: It's the why. The other thing, I think, when you start talking about why, your people are also going to interact with it, and sometimes it broadens the scope and you learn something. Right. I sometimes find that we're solving a problem and in the midst of talking about that problem and talking about the solution, I'm fascinated. What I can learn when somebody else goes, well, hey, do you know about this? Or how about this? Or what if we did something different? And I think when you enable your teams to talk about those things and talk about it that way, it's a better. It's a better environment and a better result.
Speaker B: I agree 100% with that. And in fact, one of the things that I find most valuable, um, and we're going to get to the incident response issue here in a minute, but when we're doing incident response preparation is getting our people together in a room, and we may call it a tabletop exercise, or we may call it anything but just getting people in a room together and talking, you start to learn perspectives that you never understand in a vacuum.
Speaker C: Agreed. I agree with you on that. And I do think one of the best things you can do is build those relationships so that you understand how people work and how they think and also the structure of their teams before you have a crisis. It's really difficult when you're having a bad day to also have to make first introductions and understand the workings of a team. Um, and if you've done that groundwork, then you're starting further off.
Speaker B: Yeah, yeah, you really are. I mean, you know, um, Jenny, you and I could sit here and talk about this all day, but there was, there was a reason. A year ago or over a year ago, I said, I have to get Jenny on my show. I have to have this conversation with you because you were speaking at the Advanced in House Council conference, um, back in August of 24, and you did a presentation, um, and you had a co presenter who did a fabulous job as well. And y' all were talking about a crisis you had experienced. And as you're doing that, I'm sitting there taking down notes going, oh, my God, this is like mirroring what we do in cyber crisis management.
Speaker C: Yeah.
Speaker B: You know, So I want you to tell us about experience, what's the issue? And then give us the story behind it.
Speaker C: Sure. I would say my career claim to fame is Tuesday Morning, which was an off price retailer that was started here in Dallas, had, uh, filed for bankruptcy in 2020 and as lots of companies did in retail, emerged at the end of 2020 and then unfortunately in February of 2023 filed for bankruptcy again and ultimately, um, sadly was liquidated and we closed the doors and I was one of the two last employees standing that closed the doors at Tuesday Morning. Um, it was a beloved job, a incredible Dallas company.
Speaker B: I love Tuesday Morning.
Speaker C: Yeah. And it was in like 47 states at one point. Um, so it was really a challenging time. Um, and to go from in February of filing bankruptcy to ultimately we handed the keys over to a trustee about August 1st. It was strap in and go as fast as you possibly can. I mean it was lightning speed all of those days. And, um, a little bit undetermined because we weren't expecting to liquidate when we filed in February. Um, and so that's been really my big thing, um, probably for my career of what I've done so far.
Speaker B: Yeah. And so that really struck me, number one, because we're now seeing companies that have massive cyber attacks end up in bankruptcy. So there's already that connection between cyber attacks are leading to bankruptcy. And one of the most notorious of those is, uh, the vodka, Stoli Vodka. They ended up in bankruptcy and they tied that to a ransomware attack. But that really wasn't the key point that struck me. It was how you managed that crisis situation and the story you told of managing that. Um, really from the beginning, you know, through the, through the whole crisis.
Speaker C: Yeah, I will say it felt like a crisis from before. Obviously when you file for bankruptcy, the crisis has started before. Right. And it's a little bit of a quiet crisis because the business is having some issues and so you're really pushing to work at this. So by the time you file, you've been in that crisis for a bit. And, and sometimes when you file, um, it feels a little like you step off the gas at first because you're going to have different interests. With the Tuesday morning, the second filing, it didn't feel like that. It felt like all of a sudden we were really flying down 635 and it, um, wasn't going well. Um, and so you really are trying to manage through that, but you also still have that whole time you're in the crisis. You still have fiduciary duties and your fiduciary duties extend obviously to your shareholders and your investors. But you also feel very compelled to have a duty to the employees who are still there. Um, and you have a duty to your customers still. Um, we, as a leadership team, as that happened, really felt those interests. Um, and we wanted to close the business well. It wasn't just, let's burn it down and be done. Ah. And I think that we felt that, that, um, burden to do it and finish well all the way through. And it was brought to our attention pretty early on, like, hey, you're very vulnerable as a company now as you've declared bankruptcy and as you're wrapping up, because everybody is aware that you're laying off people and how it's going. And so we felt a real heightened sense of awareness, uh, what do we do to take care of things as they're closing.
Speaker B: Yeah, you know, I've never been through that process. I'm not a bankruptcy lawyer, so I don't know how to counsel a company through that. But I know how to do it through the cyber crisis.
Speaker C: Right.
Speaker B: And that's what I do. And so the parallels to things happening very quickly, that, that was one of the first things is you don't plan for this. I mean, uh, we plan for cyber. Right. We plan, do our contingency plan, but you never know what's going to actually happen. That's right. When it happens.
Speaker C: I completely agree. I think you're planning and you're planning and doing what you can, but it's always going to have a pivot. It's always going to be, and you've said something to me before that I always hold on to that, um, when you have a cyber attack, because they're going to happen, you're the only per. You're the victim that gets blamed. Right? Yeah. And I think thinking about it that way, that in the midst of it, you, this is happening to you, it's happening to your company and you're having to deal with it. But you are also in a way in trouble. Right. And you're going to have to answer for what you do and how you do it. And that's a real struggle to balance all of those needs. Um, and all of it. I do think when you are dealing with a cyber issue, it's interesting. The trickle effect out of that is it's one of if you. That is not contained. Right. So like if you have an, an HR type crisis, you are going to deal with your HR team and get through that. And, and there may be some ancillary teams that are involved in that. But when you're dealing with an IT type Crisis or an IT type issue, all of a sudden, everybody's in the room and at the table and has to have a voice. Uh, and I think getting through that makes it a very interesting experience, especially for lawyers, because they are looking to you to lead and to guide along with that IT team.
Speaker B: Yeah, yeah. I mean, that's so true. The it is to me, one of the unique characteristics of a cyber attack is that you are the victim of an attack. But in law, regulation, even public opinion, you. I use the word transmogrified, you get transmogrified from the victim to now the wrongdoer. That's for allowing this to happen to you. And it sounds like there are some similarities in how you're treated when you go through that bankruptcy process. Yeah, but what? Two, Two key points that jump out at me right there. One, the value of your team. And I remember you talking about the team you relied on and starting with
Speaker C: your outside counsel, 100%. Um, I can tell you, interestingly enough, we're close to the end of 2025 without question the attorney, outside counsel. I've talked to you the most this year, and not dealing in crisis is my privacy cybersecurity lawyer. Um, there's no, there's not. Second doesn't come close to first. I, uh, think companies have a real heightened sense of awareness and appreciation. Think boards hold you to that standard, and I think our communities do as well. Um, I think the fact that people trust us with personal information or information they deem, uh, sensitive makes, uh, us have to rise to the level of the occasion of keeping that. Right. And it's never been more critical. And then you think also, too, that it is every state your way. Right. Nobody necessarily is doing it the same. And so you have to meet those standards, know those rules. Going back to that governance question.
Speaker B: Yeah. Uh, yeah.
Speaker C: All across the US and elsewhere. Right. If you have GDPR or other things at play, you've got to know the sandbox and do it well because they're trusting you with their info.
Speaker B: And it goes back to that duty. It's. I mean, you're a steward of other people's sensitive personal information.
Speaker C: Right.
Speaker B: And we have an obligation to care for that.
Speaker C: That's right. And I think too, um, I never want to lose sight that we have customers who have shared information with us. We also have our employees, and we have applicants, and sometimes we have information from vendors, and we're always looking for, hey, uh, what are we doing with this? And are we handling it appropriately? Right. Um, so that we can move our business forward because that is in the business's best interest.
Speaker B: Oh, absolutely. And you know, you know, uh, being in retail, that you have customer information information and you have business partner information. But what a lot of companies forget about, especially Those in the B2B space, um, they think, oh, we don't have to worry about this. They forget about their employee information.
Speaker C: Absolutely. And your employees don't forget.
Speaker B: No, they know, ah, especially former employees.
Speaker C: It all comes back. Right. All of a sudden when you exit for a new opportunity, it all comes back. Now, I agree with that. And, and I think about it as. It's not. It's my information. Right. And it's people whose names I know and care about at the company. And so I think when you personalize it that way, that makes it a little bit easier. Um, and it goes back to what you were saying about the. Why. Um, I always want to be really transparent. Ah, when we're talking about a new policy of, uh, how does this affect us? Like, go ahead and answer the question for everybody in the room. Uh, does this impact them personally or does it impact only others? Like, just get it out there and tell people. And sometimes feeling that personal responsibility creates better compliance.
Speaker B: Yeah, yeah. And, you know, I know you and I have talked a little bit about AI governance, and we're going to talk about that in the future. That's going to be another podcast episode. Um, but, but those are the same principles. You know, we're, we're now introducing a tool that can take the errors that happen right now with humans and make them exponential errors, you know, and builds on the same foundations of protecting the information.
Speaker C: Absolutely. And it's a tool that we are responsible for. And so you have to create a sense of responsibility and culpability around that. Um, I think AI is such an interesting Pandora's box of I don't know where we're going to end up. And I think it's really hard sometimes to. For a company to be held accountable for what a tool did, but we use the tool, we picked it up, and so we own it. But navigating those waters is going to be very interesting.
Speaker B: Yeah, you know, um, it's interesting you say that. I did a presentation a couple of weeks ago at, uh, DBU talking about, um, that agency relationship of, uh, when the tool speaks for you and your responsibilities. And there are several situations where AI chatbots have made promises and, you know, things that, that were not accurate. And the, the most notorious one was Air Canada, where the chat bot made a promise to through the. The chat over the bereavement policy for the airline. And the person then took them at that and they denied responsibility and went to court.
Speaker C: Sure.
Speaker B: You know, over that. And the court said, no, you're responsible for what you're doing.
Speaker C: Absolutely.
Speaker B: And that's agency principles.
Speaker C: It is, it is. Um, I think when we accept and embrace agency as opposed to trying to push it away, um, I think we're all the better for it.
Speaker A: But.
Speaker C: But man, that bite of responsibility always hurts.
Speaker B: Yeah. And, you know, a big, A big feature there is transparency.
Speaker C: Yeah.
Speaker B: Um, and that's something that we hear over and over in AI now. Ah, governance is transparency. But in the world of crisis management. So I've been handling crisis in a sense my whole career. But really the last 15 years have done so much with the data breach and the. Yeah. Ransomware stuff there. I've, uh, seen the trends change. Like, for the early years, we worked really hard to not have to disclose if the laws didn't require, because that was the state of the industry. Over the last several years, we've really seen a move to more transparency. Um, and that brings me back to your. Your situation of handling crisis. Previously, I remember you talking about how you communicated with the employees.
Speaker C: Yeah.
Speaker B: And that there was a fear that if I tell them too much, they're gonna all leave.
Speaker C: Yeah.
Speaker B: But you didn't do the safe thing. You went with transparency.
Speaker C: We did. Um, I. There was a real fear of. When you start talking about it in reality, of like, we know the company is closing. We know this is a tree liquidation. But to get through that liquidation process, you need a certain number of people. You still need some back office. And I thought, there's no way people are going to stay. And I was floored at how many people stayed because they wanted to finish well, that it personally mattered to them to finish well. Um, and so one of the things we really, uh, prioritized doing was telling hard truths. And also in telling hard truths, uh, we would sometimes have to do the. I'm telling you this today, and it could be wrong tomorrow. I'm telling you this today, and we may have to pivot tomorrow was just owning that it was moving at such a pace that we could put out wrong information to our employees. And we didn't love that, but we could take it back. And that they knew we were going to give them the best information we had at the time. So as much as we could, they didn't have to guess. Now, I think that was our intent. Um, I think some Employees experienced it that way. And I think other employees still felt like it wasn't enough. And, and I'm real empathetic to when you close up a business to how other people react and feel, to their personal experience as an employee and that, like, it's just tough.
Speaker B: I mean, it's life changing for everyone.
Speaker C: Absolutely, absolutely.
Speaker B: You know, and, and I mean, and so in part four of the book, I talk about crisis management and the whole. And there's a chapter in there about crisis communication and we talk about the transparency part. But what it really seems to come from, um, is caring. It's caring about the people who are being at stake.
Speaker C: Yeah. I think you have to care. And I think sometimes, especially when you're dealing with a technology component, your, what you may want to do is take a step back and make it not about the people and make it about the thing because that's easier to talk about. But I think when we can humanize the relationship between technology and people in a cyber attack or a breach, um, or anything like that, you're in a better place because ultimately it's going to circle back to people. You're just trying to figure out how all of that works, uh, together. Because I think that's an interesting braid of people and technology.
Speaker B: Yeah.
Speaker C: Um, and how do you support and do that? And I would say too, anytime you're talking about it, you want to be as transparent as you can, but you don't want to be a sucker. Well, right. Like you can't tell everything.
Speaker B: You can't. And that's really where it brings us, is there's a fine line we're trying to find that golden mean, if you will, of uh, being as transparent as we reasonably can. But we can't be reactionary. Like, we can't just be emotionally reactionary. And I've seen it happen in the minute you learn something, you're blasting it out on your social media or whatnot. You. Because now you're going to put people in fear that may not be justified. And so to me it's finding that balance between, um, what do we reasonably believe? And there's an old saying that I love to use in this, and it's a military saying, first reports from the front line are usually wrong. Like when you're in the fog of war and this, all the stuff you're hearing at first, it's not accurate usually. So you don't want to be reactionary and start reporting on all the fears. You got to investigate a reasonable amount to understand what's truly going on. But then you have to be transparent as much as you can with that information.
Speaker C: Agreed. And I think you have to really lean on your technology team, um, to tell you what you can as far as the nuts and bolts, what you should and what you can say. Um, and then lean on legal for what is required. And there's some middle ground between the two of those, but. Absolutely. I need an expert who can tell me, hey, I. You can talk about this in this point of sale issue. Right. And you can talk about what's happened, but we need you to leave off these pieces because this makes us more vulnerable in the future. Um, and that makes sense, right, that you've got to have both sides that that can come together and. And I don't have the expertise to pick up all the time on, um, what all should be shared.
Speaker B: Yeah, I mean, that's what it really comes back to is that need to collaborate.
Speaker C: Yeah.
Speaker B: That need to have a good team to know who our team is, what their skill set and their expertise is. And we're not going to learn that on the day of the battle.
Speaker C: That's right.
Speaker B: We're going to know that through our relationship leading up to that, and then trust each other. And that comes from the relationship.
Speaker C: I think it all. It all beats back. There's nothing. I think it's so funny that I would say legal and the technology space. Nobody has more three letter acronyms and then these two spaces and you need to learn each other's freehand and what people talk about and how that that all plays together and have. I always think I need at least a floor. Even if she is in a pretty floor, I need at least a floor of understanding to build upon when a crisis happens. Um, and then the whole time we're in crisis, I absolutely need a partner who can stop in the midst of it and go, oh, uh, you need a technology education for a piece here because you're not appreciating what's happening because this is outside your scope and they need to tell you. And then they also need to listen if, like, this is really the law and this is really what we have to do. And so tell me how we can be compliant. And sometimes that's real challenging, you know?
Speaker B: And that comes back to something you and I were talking about before we started here today, and that is ego. Um, one of the reasons I, uh, wanted to write the book was about the problem I've seen of ego, both in the legal side and on the CSO side, because those are both Protector roles. Right. They're. They're very strong protective in what they do. And you tend to get people with very strong personalities many times, and ego can become such an enemy in that process. But what you're talking about there is having the ability to listen to one another, learn and know. Hey, maybe what I thought I knew, I don't know. Help me understand.
Speaker C: Yeah, well. And things change so fast. Like, I feel like sometimes I've finally gotten a grasp of technology from my job, from my kids. I have finally learned something. Maybe it's about how I was really pleased I learned how cookies worked, um, on websites. And then it changes because it moves and changes so fast. It keeps me super humble all the time, talking to it, because I'll just start going down the road of, like, I know that you have to do this for SoC2 compliance. And I'm thrilled I've learned what SoC2 compliance is. And they're like, well, we have to do this for some other new acronym. I'm like, ah, I thought I had learned. And yet there's a. There's a new brick right down that road.
Speaker B: We've got ice.
Speaker C: So it is all back to that. It's all back to the acronyms. And so I think doing that keeps me curious. But also, I eat humble pie way more than I enjoy.
Speaker B: I do. I do as well, Jenny. Um, you know, I tell people, because these days I'm doing more AI than I'm really doing. Anything is if someone tells you they're an expert at this, be very careful, because they probably don't know what they don't know. Like, there is so much information out there in the privacy space now in the AI space, and the laws and the regulations and the standards and best practices, and then the technology constantly changing. You really can't know it all. You have to stay humble.
Speaker C: Oh, uh, I think the only thing I'm an expert in is being curious.
Speaker B: Yeah.
Speaker C: I don't think, um, I have another thing I could call myself an expert on. And I was recently talking to my outside counsel, and I said, I feel like as a year of being really into some privacy issues, I said, I don't feel like an expert or even close to that. I said, now I'm more afraid of what I don't know. She goes, that's what's happened. You. You're now far enough down the rabbit trail that you can see what you don't know. And. And I think that's super interesting that the more I learn, the more I realize I need More, more support. And I need more of a team to, to come beside and teach me what I just don't know.
Speaker B: Yeah, I mean, I agree 100%, and I feel that way in my practice and in, in everything that I do, because we have to depend on that team because none of us know all of it.
Speaker C: But I love a lawyer who will tell. Tell me, I don't know the answer, but I'll come back to you. I take great comfort. And if an outside counselor goes, oh, that's interesting. I don't know right off the top, but I'm sure I'm going to have an answer for you shortly. Uh, and I think that ability to be transparent in that answer helps, uh, a whole lot now, like an IT team, he'll go, that's, that's crazy. We've never thought of that. I don't know either. And they'll come back and go, but we can, we can figure it out because that's all we're looking for. Right. Is to, to name what, what we may need to be concerned about and move forward with that.
Speaker B: That's right. And know that it may change.
Speaker C: Oh, it's going to change 10 times. As we're moving forward, everything's going to change.
Speaker B: And, uh, and to be flexible for that. So that brings us to the super grades. Right back to the super gray that I'm going to get that to stick.
Speaker C: Oh, we'll see.
Speaker B: Uh, well, Jenny, this has really been wonderful. Um, do you have any takeaways that you would give to others for managing a crisis or just how to cope with it based upon the experiences you've had?
Speaker C: Sure. I, I think the one thing I learned, um, is in crisis is everything moves fast, so you move slow. Uh, I had a mentor who told me you have to always be the calmest on the outside person in the room. You do not have to be calm inside. Um, but talk slower and think a little bit slower, um, in a time of crisis. And I think that's right. And I think the other thing is, in crisis, admit where you are and tell the truth as much as you possibly can. Be transparent, like we talked about earlier, um, and then find as much as you can find an expert on all of the subtopics because you, um, you can never do it all at all.
Speaker B: Well, that's just a wonderful place to end on. Thank you so much, Jenny, for joining me. Um, as expected, our time just flew by. I think we could go on talking about this all day, but I really appreciate you taking the time.
Speaker C: Thank you so much. I wish you all the best.
Speaker B: Well, I appreciate it, and thank you for joining in and watching this episode of the GCC Connection show, and I hope to see you back next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.